Nikkei discloses breaches of employees’ Microsoft, Google email accounts
Summary
Japanese publishing giant Nikkei has disclosed a data breach where attackers accessed two employee email accounts. One of the compromised accounts was used to send thousands of phishing emails to Nikkei's customers and business partners. The attackers also gained access to some sensitive information from internal communications.
IFF Assessment
This incident represents a direct attack on a company's infrastructure, leading to potential data exposure and further phishing campaigns, which is bad news for defenders.
Defender Context
This incident highlights the persistent threat of credential stuffing and account takeover, even at large organizations. Defenders should emphasize strong authentication methods, multi-factor authentication (MFA), and user education on phishing awareness to prevent similar compromises. Monitoring for unusual outbound email activity is also crucial.